VDB
Sign up
—

PYSEC-2026-897

Plone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable

Quick fix

PYSEC-2026-897 — plone: upgrade to the fixed version with the command below.

pip install --upgrade 'plone>=4.0.10'

Details

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/plone
Introduced in: 4.0Fixed in: 4.0.10
Fixpip install --upgrade 'plone>=4.0.10'

References